BigHugger
sk Skill · mukul975

verifying-build-provenance-with-slsa-sigstore

Verifies artifact signatures and SLSA provenance using Sigstore's cosign (verify, verify-attestation, verify-blob-attestation) and slsa-verifier (verify-artifact), enforcing keyless OIDC builder identity and source repo against SLSA Build levels. Use in CI/CD before deploying artifacts, when consuming third-party attestations, establishing a SLSA Build L3 pipeline, or confirming provenance during incident response…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonprovenancecosignsigstorekeyless-signingslsacode-signingattestationsupply-chain
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python